7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24594
Translate WordPress – Google Language Translator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-40578
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2021 2 PoCs

Authenticated Blind & Error-based SQL injection vulnerability was discovered in Online Enrollment Management System in PHP and PayPal Free Source Code 1.0, that allows attackers to obtain sensitive information and execute arbitrary SQL commands via IDNO parameter.

CVE-2021-45086
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.

CVE-2021-37922
Software Genérico General
N/A
UNKNOWN
EPSS
26.0%
2021 1 PoC

Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another.

CVE-2021-45268
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading a maliciously add-on with crafted PHP file. NOTE: the vendor disputes this because the attack requires a session cookie of a high-privileged authenticated user who is entitled to install arbitrary add-ons

CVE-2021-45078
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.

CVE-2021-33793
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office document conversion.

CVE-2021-24545
WP HTML Author Bio Web Windows
N/A
UNKNOWN
EPSS
13.3%
2021 CWE-79 3 PoCs

The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripting attacks against users, which could potentially lead to privilege escalation when an admin view the related post/s.

CVE-2021-26388
EPYC™ Processors General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memory contents, resulting in a potential denial of service.

CVE-2021-35061
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in DRK Odenwaldkreis Testerfassung March-2021 allow remote attackers to inject arbitrary web script or HTML via all parameters to HTML form fields in all components.

CVE-2021-26353
3rd Gen EPYC General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partially initialized state potentially resulting in loss of memory integrity.

CVE-2021-24320
Bello - Directory & Listing Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
50.3%
2021 CWE-79 2 PoCs

The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_bb_listing_field_distance_value, bt_bb_listing_field_my_lat_default, bt_bb_listing_field_keyword, bt_bb_listing_field_location_autocomplete, bt_bb_listing_field_price_range_from and bt_bb_listing_field_price_range_to parameter in ints listing page, leading to reflected Cross-Site Scripting issues.

CVE-2021-29133
Software Genérico General
N/A
UNKNOWN
EPSS
2.0%
2021 1 PoC

Lack of verification in haserl, a component of Alpine Linux Configuration Framework, before 0.9.36 allows local users to read the contents of any file on the filesystem.

CVE-2021-24289
Store Locator Plus for WordPress Web Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-269 1 PoC

There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin.

CVE-2021-33503
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.

CVE-2021-29662
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVE-2021-24582
ThinkTwit Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The ThinkTwit WordPress plugin before 1.7.1 did not sanitise or escape its "Consumer key" setting before outputting it its settings page, leading to a Stored Cross-Site Scripting issue.

CVE-2021-33294
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file.

CVE-2021-30180
Apache Dubbo Web
N/A
UNKNOWN
EPSS
4.4%
2021 1 PoC

Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these YAML rules, Dubbo customers may enable calling arbitrary constructors.

CVE-2021-37931
Software Genérico General
N/A
UNKNOWN
EPSS
37.4%
2021 1 PoC

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.